
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-85053 is a high-severity vulnerability described as "Improper resource exposure in CacheStorage" in Google Chrome. It allows a remote attacker to execute arbitrary code inside the Chrome sandbox by tricking a user into visiting a crafted HTML page. The vulnerability affects all versions of Google Chrome prior to 152.0.7977.82 and was reported by Salvatore Gulizia (alias: Serotav) on 2026-08-26. It was publicly disclosed on September 3, 2026, as part of a 12-fix stable channel update. The CVSS v3.1 base score is 8.8 (High) (Chrome Releases, GitHub Advisory).
The root cause is classified under CWE-668 (Exposure of Resource to Wrong Sphere) and CWE-94 (Improper Control of Generation of Code), indicating that Chrome's CacheStorage API improperly exposes resources to an unintended context, enabling code injection within the sandbox. An attacker exploits this by serving a specially crafted HTML page that manipulates CacheStorage in a way that triggers the improper resource exposure, ultimately achieving arbitrary code execution within the Chrome renderer sandbox. No privileges are required on the attacker's side, but user interaction (visiting a malicious page) is necessary. The Chromium issue tracker entry is tracked under issue #552689418 (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, achieving high impact on confidentiality, integrity, and availability of the sandboxed environment. While the sandbox limits direct host OS access, sandbox escape chained with this vulnerability could lead to broader system compromise. Data accessible within the browser context — including cached content, session data, and credentials — may be exposed or manipulated (GitHub Advisory, Feedly).
As of the disclosure date, there is no public proof-of-concept exploit specifically for CVE-2026-85053, and no evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.31%, placing it in the 22nd percentile for exploitation likelihood within 30 days. Notably, a separate vulnerability in the same Chrome update (CVE-2026-85046, a V8 type confusion bug) was confirmed by Google to have an active in-the-wild exploit, but CVE-2026-85053 is not listed as exploited. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Chrome Releases, GitHub Advisory).
Google has released a fix in Chrome stable channel version 152.0.7977.82 (Linux) and 152.0.7977.82/.83 (Windows/Mac). Users and administrators should update Google Chrome to version 152.0.7977.82 or later immediately. As a general precaution, users should avoid visiting untrusted or suspicious websites, since user interaction (visiting a crafted page) is required to trigger this vulnerability. No configuration-based workaround is available; patching is the only definitive remediation (Chrome Releases, Microsoft MSRC).
The CIS issued an advisory noting that multiple vulnerabilities in this Chrome update, including CVE-2026-85053, could allow arbitrary code execution (CIS Advisory). Media coverage largely focused on the co-disclosed CVE-2026-85046 (V8 type confusion), which had a confirmed in-the-wild exploit, with outlets such as HotHardware urging billions of Chrome users to update immediately. CVE-2026-85053 received less individual attention but was covered as part of the broader Chrome security update. Linux distribution maintainers for Fedora, Debian, and openSUSE also issued advisories and updated Chromium packages in response to this update batch.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."